7558 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2023-5961
ioLogik E1200 Series Web
8.8
HIGH
EPSS
0.1%
2023 CWE-352 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can exploit this vulnerability to trick a client into making an unintentional request to the web server, which will be treated as an authentic request. This vulnerability may lead an attacker to perform operations on behalf of the victimized user.

CVE-2023-21846
BI Publisher (formerly XML Publisher) Database
8.8
HIGH
EPSS
1.1%
2023 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2023-0875
WP Meta SEO Web Database Windows
8.8
HIGH
EPSS
0.7%
2023 1 PoC

The WP Meta SEO WordPress plugin before 4.5.3 does not properly sanitize and escape inputs into SQL queries, leading to a blind SQL Injection vulnerability that can be exploited by subscriber+ users.

CVE-2023-43318
Software Genérico General
8.8
HIGH
EPSS
0.5%
2023 3 PoCs

TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.

CVE-2023-35808
Software Genérico Web
8.8
HIGH
EPSS
0.4%
2023 2 PoCs

An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in the Notes module. By using crafted requests, custom PHP code can be injected and executed through the Notes module because of missing input validation. Regular user privileges can be used to exploit this vulnerability. Editions other than Enterprise are also affected.

CVE-2023-7074
WP SOCIAL BOOKMARK MENU Web Windows
8.8
HIGH
EPSS
0.1%
2023 1 PoC

The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.

CVE-2023-35674
🔥 KEV Android Windows
8.8
HIGH
EPSS
0.1%
2023 2 PoCs

In onCreate of WindowState.java, there is a possible way to launch a background activity due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2023-2934
Chrome General
8.8
HIGH
EPSS
0.8%
2023 1 PoC

Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2023-34448
grav Web
8.8
HIGH
EPSS
8.8%
2023 CWE-20 1 PoC

Grav is a flat-file content management system. Prior to version 1.7.42, the patch for CVE-2022-2073, a server-side template injection vulnerability in Grav leveraging the default `filter()` function, did not block other built-in functions exposed by Twig's Core Extension that could be used to invoke arbitrary unsafe functions, thereby allowing for remote code execution. A patch in version 1.74.2 overrides the built-in Twig `map()` and `reduce()` filter functions in `system/src/Grav/Common/Twig/Extension/GravExtension.php` to validate the argument passed to the filter in `$arrow`.

CVE-2023-50015
Software Genérico General
8.8
HIGH
EPSS
0.3%
2023 1 PoC

An issue was discovered in Grandstream GXP14XX 1.0.8.9 and GXP16XX 1.0.7.13, allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity token.

CVE-2023-32697
sqlite-jdbc Database
8.8
HIGH
EPSS
5.5%
2023 CWE-94 1 PoC

SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.

CVE-2023-5448
WP Register Profile With Shortcode Web Windows
8.8
HIGH
EPSS
0.2%
2023 CWE-352 2 PoCs

The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.9. This is due to missing or incorrect nonce validation on the update_password_validate function. This makes it possible for unauthenticated attackers to reset a user's password via a forged request granted they can trick the user into performing an action such as clicking on a link.

CVE-2023-0951
Devolutions Server Web
8.8
HIGH
EPSS
0.4%
2023 1 PoC

Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perform privileged actions.

CVE-2023-32563
Avalanche General ⚡ nuclei
8.8
HIGH
EPSS
93.0%
2023 0 PoCs

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

CVE-2023-23388
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
17.7%
2023 CWE-681 1 PoC

Windows Bluetooth Driver Elevation of Privilege Vulnerability

CVE-2023-24653
Software Genérico Database
8.8
HIGH
EPSS
0.2%
2023 2 PoCs

Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.

CVE-2023-2573
EKI-1524 General
8.8
HIGH
EPSS
1.4%
2023 CWE-78 4 PoCs

Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.

CVE-2023-31433
Software Genérico Database
8.8
HIGH
EPSS
0.5%
2023 2 PoCs

A SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated attackers to execute SQL statements via the welche parameter.

CVE-2023-50233
Ignition General
8.8
HIGH
EPSS
3.7%
2023 CWE-22 1 PoC

Inductive Automation Ignition getJavaExecutable Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a malicious server. The specific flaw exists within the getJavaExecutable method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context

CVE-2023-43236
Software Genérico General
8.8
HIGH
EPSS
1.9%
2023 1 PoC

D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.